Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 1Objective 1

Information Security Threats and Vulnerabilities CCT Practice Questions (Page 9)

Part of the Information Security Threats and Attacks domain, which makes up ~12% of our current practice bank.

47questions here
10free pages
7concepts

Questions 41–45

  1. 41expert · hard

    A company has a public-facing web application and an internal employee portal. The security team is conducting a risk assessment and wants to reduce the attack surface. Which of the following actions would most effectively reduce the attack surface?

    Select an answer first
  2. 42application · medium

    A vulnerability assessment reveals that a web application has a SQL injection vulnerability that could allow an attacker to read the entire customer database. The application is internet-facing and is the company's primary revenue source. What is the most appropriate risk treatment?

    Select an answer first
  3. 43foundation · easy

    Which type of threat actor is typically motivated by financial gain and uses sophisticated techniques to steal data or money?

    Select an answer first
  4. 44application · medium

    A security analyst is conducting a vulnerability assessment of a new web application. The scan identifies several missing security headers and a potential SQL injection point. The analyst must prioritize which findings to report to management. Which approach best aligns with the purpose of a vulnerability assessment?

    Select an answer first
  5. 45foundation · easy

    Which of the following best describes a phishing attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.